WINBASE.IO — Privacy Policy
pursuant to Art. 13, 14 GDPR — as of June 2026 | Version 2.0
1. Controller
Diektec UG (haftungsbeschränkt) | Randstr. 1, 22525 Hamburg | Germany
VAT ID: DE464148058
E-mail: privacy@winbase.io | Website: winbase.io
We are not required by law to appoint a data protection officer (§ 38 BDSG, German Federal Data Protection Act). For any data protection question, please contact privacy@winbase.io.
2. Allocation of data protection roles
Core principle: separate controllers — no processing agreement
- Winbase (Diektec UG (haftungsbeschränkt)) is an independent controller for operating the platform.
- Creators are independent controllers for data arising from their own promotions.
- No general data processing agreement (DPA) is concluded.
Winbase is the controller for:
Registration, user accounts, authentication, security measures, fraud detection, platform operation, communication systems, technical logs and transparency features.
Creators are independent controllers for:
Personal data arising from their own promotions, in particular contacting winners, shipping and any additional data collection.
Winner data is passed to a creator only to the extent necessary to hand over the prize (Art. 6 (1) (b) GDPR, performance of the contract with the entrant). Creators use this data solely for that purpose and delete it once the purpose has ceased to apply.
Data subjects exercise their rights in respect of Winbase processing against Winbase (privacy@winbase.io). For creator processing, data subjects must be referred directly to the creator.
3. Overview of processing activities
| Processing activity | Categories of data | Legal basis | Retention |
|---|---|---|---|
| Registration & account | E-mail, username, password (hashed), mobile number, date of birth, address, timestamps | Art. 6 (1) (b) GDPR | Until the account is deleted |
| Use of the platform | Entry data, ticket numbers, timestamps | Art. 6 (1) (b) GDPR | Lifetime of the account |
| Subscriptions / payment | Billing data, payment status (no raw card data) | Art. 6 (1) (b) GDPR; § 147 AO (German Fiscal Code) | 10 years |
| Creator approval | Proof of identity, address and trade registration | Art. 6 (1) (c), (f) GDPR | Lifetime of the account + 3 years |
| Winner data | Username, contact details (handing over the prize) | Art. 6 (1) (b) GDPR | Until the prize has been handed over |
| Security / logs | IP address (anonymised after 7 days), browser information | Art. 6 (1) (f) GDPR | 30 days |
| Cookies / tracking | Strictly necessary cookies + opt-in analytics | Art. 6 (1) (a) (opt-in) / (f) (necessary) GDPR | Per the cookie policy |
| E-mail communication | Enquiries, support | Art. 6 (1) (b), (f) GDPR | 3 years |
4. Disclosure of data
4.1 Disclosure to creators
Winner data is passed to the creator only to the extent necessary to hand over the prize (Art. 6 (1) (b) GDPR, performance of the contract with the entrant). Disclosure is limited to the necessary minimum. No processing agreement is concluded, because creators are independent controllers.
4.2 Service providers (Winbase sub-processors)
To provide the platform, Winbase uses the following categories of service providers (each under its own processing agreement with Winbase):
- Hosting and infrastructure providers (EU/EEA preferred)
- E-mail delivery service (transactional e-mail)
- Payment service provider
- CDN / DDoS protection
- Analytics and monitoring services (only with consent)
A current list of service providers is available on request (privacy@winbase.io). Details of the individual services: section 8.
4.3 Transfers to third countries
Where service providers outside the EU/EEA are used, transfers take place solely on the basis of appropriate safeguards under Art. 44 et seq. GDPR (EU standard contractual clauses or an adequacy decision).
4.4 Public authorities
Data is disclosed to public authorities only where required by law.
5. Your rights as a data subject
| Right | Content |
|---|---|
| Access | Art. 15 GDPR: right of access to the data stored about you |
| Rectification | Art. 16 GDPR: right to have inaccurate data corrected |
| Erasure | Art. 17 GDPR: right to erasure (“right to be forgotten”) |
| Restriction | Art. 18 GDPR: right to restriction of processing |
| Portability | Art. 20 GDPR: transfer in a machine-readable format |
| Objection | Art. 21 GDPR: objection to processing based on legitimate interests |
| Withdrawal | Consent can be withdrawn at any time with effect for the future |
| Complaint | Art. 77 GDPR: complaint to the competent supervisory authority |
Requests: privacy@winbase.io
Competent supervisory authority: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI), Ludwig-Erhard-Str. 22, 20459 Hamburg, Germany. A list of all German state data protection authorities is available at bfdi.bund.de. If you are resident in another country, you may also lodge a complaint with the supervisory authority of that country.
Deleting your account and data
You can delete your account and all associated data yourself: in the dashboard under Settings → Delete account. Deletion takes effect immediately and covers profile data, avatar, entry data and active subscriptions (Stripe subscriptions are cancelled automatically).
Alternatively you can request deletion in writing: privacy@winbase.io. We will process the request within 30 days.
If referral commissions have produced credit notes subject to statutory retention (§ 147 AO, German Fiscal Code, 10 years), your account is not deleted in full but anonymised: all personal profile data (name, e-mail, address, phone number, payment and payout details) is removed and your access is permanently blocked. Only the anonymised accounting record subject to retention remains, with no personal reference.
6. Security measures (Art. 32 GDPR)
- TLS encryption (HTTPS, TLS 1.2 or higher)
- Role-based access control (least privilege)
- Two-factor authentication for administrator access
- Pseudonymisation of entrant lists in public proofs
- IP anonymisation after 7 days at the latest
- Regular backups and restore testing
- Logging of administrative access
- Regular security reviews and patch management
Raffle winners are determined by a deterministic algorithm (SHA-256 + Bitcoin block hash) that takes no personal characteristics of entrants into account. No automated decision-making within the meaning of Art. 22 GDPR takes place.
7. Creators’ data protection obligations
Creators who process entrant data via Winbase are independent controllers. By accepting the terms and the creator data protection clause they undertake to:
- inform entrants about the processing in accordance with Art. 13, 14 GDPR
- provide their own, legally compliant privacy policy for their promotions
- use entrant data they receive solely for the promotion concerned
- delete data without undue delay once the purpose has ceased to apply
- report data breaches without undue delay to privacy@winbase.io
- indemnify Winbase against claims arising from data protection breaches
Note: no processing agreement between Winbase and creators
Because creators are independent controllers, no data processing agreement is concluded. Creators’ data protection obligations are established with binding effect by their acceptance of the terms and of the creator data protection clause (checkbox F in the approval process).
8. Cookies and tracking
Strictly necessary cookies are set without consent (Art. 6 (1) (f) GDPR). For non-necessary cookies, prior consent is obtained (Art. 6 (1) (a) GDPR). Consent can be withdrawn at any time by deleting the browser cookies — the banner will then appear again on your next visit.
Details and opt-out: winbase.io/cookies
8.1 Strictly necessary cookies
| Service | Purpose | Provider | Retention | Legal basis |
|---|---|---|---|---|
| Supabase Auth | Session cookie for login status, user authentication, token refresh | Supabase Inc., EU hosting (Frankfurt, aws-eu-central-1) | Session / max. 7 days | Art. 6 (1) (b) GDPR |
| Stripe | Payment processing, fraud detection (__stripe_mid, __stripe_sid). These cookies are only set when you interact with checkout or billing. | Stripe Inc., PCI-DSS certified | Session / up to 1 year | Art. 6 (1) (b) GDPR |
| next-intl (language) | Stores your preferred language (de/en). Purely local in the browser, no data transfer. | Local (no third party) | 1 year | Art. 6 (1) (f) GDPR |
| Referral code | Stores the referral code from the URL (?ref=…) locally in the browser so it can be attributed if you register later. Deleted after successful registration. | Local (localStorage) | 30 days | Art. 6 (1) (f) GDPR |
| Cloudflare Turnstile | Bot protection during registration. Turnstile analyses browser signals in the background to prevent automated sign-ups. Your IP address is briefly transmitted to Cloudflare servers in the process. | Cloudflare Inc., USA (EU SCCs, processing partly in EU data centres) | Session | Art. 6 (1) (f) GDPR |
| Cookie consent | Stores your cookie choice (winbase_cookie_consent). Purely local in the browser. | Local (localStorage) | Indefinite (can be deleted by you) | Art. 6 (1) (c) GDPR |
8.2 Analytics cookies (only with consent)
| Service | Purpose | Provider | Data | Legal basis |
|---|---|---|---|---|
| Vercel Analytics | Anonymous page views and usage statistics. No cross-site tracking, no personal data. | Vercel Inc., USA (EU SCCs) | Page URL, referrer, device type, country (anonymised) | Art. 6 (1) (a) GDPR |
| Vercel Speed Insights | Measurement of loading times (Core Web Vitals). Fully anonymised, no user identification. | Vercel Inc., USA (EU SCCs) | LCP, FID, CLS, TTFB (performance metrics) | Art. 6 (1) (a) GDPR |
8.3 Marketing cookies
No marketing or advertising cookies are currently used.
8.4 Further processing by service providers
| Service | Purpose | Provider | Legal basis |
|---|---|---|---|
| Supabase Storage | Storage of user avatars and raffle/competition images | Supabase Inc., EU (Frankfurt) | Art. 6 (1) (b) GDPR |
| Resend | Transactional e-mail (confirmations, win notifications, subscription status) and newsletter notifications (only with express consent) | Resend Inc., USA (EU standard contractual clauses under Art. 46 (2) (c) GDPR) | Art. 6 (1) (b) GDPR (transactional) / Art. 6 (1) (a) GDPR (newsletter) |
| seven.io (SMS) | Sending a one-time SMS verification code (OTP) during registration to confirm your mobile number. Only the mobile number and the six-digit code are transmitted; no other profile data. The code is valid for 10 minutes. | seven communications GmbH, Germany (GDPR-compliant, servers located in Germany) | Art. 6 (1) (b) GDPR |
| Vercel Hosting | Hosting, CDN, edge functions. Server logs (IP, user agent) for a maximum of 30 days. | Vercel Inc., USA (EU SCCs) | Art. 6 (1) (f) GDPR |
| OpenStreetMap (Leaflet) | Map display in geo-guesser challenges. Map tiles are loaded from OSM servers. | OpenStreetMap Foundation | Art. 6 (1) (b) GDPR |
| blockchain.info / blockstream.info | Retrieval of the latest Bitcoin block hash as an external entropy value for the transparent raffle draw (blockstream.info serves as a fallback source). No personal reference. | Blockchain.com / Blockstream | Art. 6 (1) (f) GDPR |
| YouTube (Google LLC) | Embedding of YouTube videos on raffle and competition pages. When an embedded video loads, your IP address is transmitted to Google servers. We use the privacy-enhanced mode (youtube-nocookie.com), so no tracking cookie is set without interaction. | Google LLC, USA (EU SCCs) | Art. 6 (1) (f) GDPR |
| Anthropic (Claude AI) | AI-assisted features: raffle builder and competition builder (creators/admins only) and the public AI chatbot “Winny”. When used, the text you enter is transmitted to Anthropic servers for processing. No personal profile data is transmitted. Under its own privacy policy, Anthropic does not retain API inputs for training purposes. | Anthropic PBC, USA (EU standard contractual clauses under Art. 46 (2) (c) GDPR) | Art. 6 (1) (b) GDPR (creator tools) / Art. 6 (1) (f) GDPR (chatbot) |
| Web Push (VAPID) | Browser push notifications for premium, creator and admin users. When enabled, a push subscription (the endpoint URL of your browser vendor and a VAPID key pair) is stored on our servers. Subscriptions can be revoked at any time in the browser or via the dashboard. | Winbase / the respective browser vendor (e.g. Google LLC, Mozilla Foundation) | Art. 6 (1) (a) GDPR |
9. Retention periods
| Category of data | Retention period |
|---|---|
| Account data | Deleted when the account is deleted, at the latest 30 days after cancellation |
| Winner data | The winner’s address and contact details are shown to the creator solely to hand over the prize and are hidden automatically at the latest 6 months after the raffle or competition ends |
| Billing / payment data | 10 years under § 147 AO (German Fiscal Code) |
| Creator verification data | 3 years after the creator relationship ends |
| Security logs / IP | 30 days (IP anonymised after 7 days) |
| Mobile number (SMS verification) | Stored for the lifetime of the account; deleted when the account is deleted |
| SMS OTP codes | Invalidated after 10 minutes or on successful verification |
| Push subscriptions | Until push consent is withdrawn or the account is deleted |
| E-mail delivery logs | Max. 30 days |
| Support communication | 3 years after the matter is closed |
10. Changes to this privacy policy
This policy will be amended in response to legal or technical changes. The current version is always available at winbase.io/datenschutz. Users are informed of material changes by e-mail.
As of June 2026 | Version 2.0
Controller: Diektec UG (haftungsbeschränkt) | privacy@winbase.io
Supervisory authority: Der Hamburgische Beauftragte für Datenschutz und Informationsfreiheit (HmbBfDI), Hamburg, Germany
This English version is a translation of the German original. In the event of any discrepancy, the German version prevails; this does not affect your rights under the GDPR.